Vulnerabilities > Cpanel > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-07-30 | CVE-2019-14414 | Unspecified vulnerability in Cpanel In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). | 2.1 |
2019-07-30 | CVE-2019-14386 | Cross-site Scripting vulnerability in Cpanel cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). | 3.5 |
2019-07-30 | CVE-2019-14389 | Unspecified vulnerability in Cpanel cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510). | 2.1 |
2019-07-30 | CVE-2019-14390 | Cross-site Scripting vulnerability in Cpanel cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). | 3.5 |
2019-07-30 | CVE-2019-14391 | Unspecified vulnerability in Cpanel cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514). | 2.1 |
2017-07-19 | CVE-2017-11441 | Cross-site Scripting vulnerability in Cpanel WHM The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297. | 3.5 |
2006-12-14 | CVE-2006-6548 | Cross-Site Scripting vulnerability in Cpanel Webhost Manager 3.1.0 Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/rearrangeacct. network cpanel | 3.5 |
2006-11-14 | CVE-2006-5883 | Cross-Site Scripting vulnerability in Cpanel 10 Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir parameters in (b) newuser.html. network cpanel | 3.5 |
2006-07-03 | CVE-2006-3337 | Cross-Site Scripting vulnerability in Cpanel Select.HTML Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter. | 2.6 |
2003-12-31 | CVE-2003-1426 | Configuration vulnerability in Cpanel 5.0 Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable. | 3.3 |